Security updates and patches are provided for the latest releases:
| Version | Supported |
|---|---|
| 0.1.x | ✅ |
If you discover a security vulnerability in PolyXML (such as memory safety bugs, buffer overflows, unbounded memory allocations, or XML entity / billion-laughs vulnerabilities), please do NOT disclose it publicly.
Instead, report security issues via:
-
GitHub Security Advisories (Preferred):
- Visit the Security tab on GitHub and click "Report a vulnerability".
-
Email:
- Send an email to bailey.tan.nguyen@gmail.com with the subject line
[SECURITY] PolyXML vulnerability report.
- Send an email to bailey.tan.nguyen@gmail.com with the subject line
- A detailed description of the vulnerability.
- A minimal XML payload and code snippet reproducing the problem.
- Impact assessment and suggested mitigations, if any.
- Initial Response: Within 48 hours.
- Triage & Patching: Within 5 business days.
- Public advisories and patched releases will be coordinated responsibly.